Impact
Cockpit‑files implements privileged operations such as changing file ownership and permissions. A timing issue—a symlink race condition—allows an attacker who has local access to the system to manipulate directory entries and win the race. By doing so, the attacker can redirect these privileged operations to arbitrary target files, leading to unauthorized ownership or permission changes. This results in compromise of system integrity and potentially availability, since critical system or application files could be altered or services rendered unusable.
Affected Systems
The vulnerability affects the cockpit-files component on Red Hat Enterprise Linux 9 and Red Hat Enterprise Linux 10 systems. No specific version information is provided in the advisory; therefore all installations of cockpit‑files on these platforms are potentially exploitable until patched.
Risk and Exploitability
The CVSS score of 6 indicates medium severity. The EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog. Because the attack requires local privilege and races within the cockpit-files process, an attacker must already have a user account on the target machine. If they can exploit the race, they can modify arbitrary file ownership or permissions, potentially taking control of system resources or disrupting service. The lack of a publicly disclosed exploit and the local nature of the threat suggest a moderate risk pending the deployment of a fix.
OpenCVE Enrichment